Thanks Scott, I just got finished reviewing data in the Google-verse and found the content you are referencing. It’s nice to have confirmation I was getting reliable hits.
In summary it seems the text that is now in 4.10 is indeed optional. What is also frustrating is the guidance info in A.4.10 refers to “the assessment requirement” – which is not a statement of fact, there is no assessment requirement. Best Regards, -Lauren Confidential – Limited Access and Use From: Scott Aldous <[email protected]> Sent: Friday, August 23, 2024 4:45 PM To: [email protected] Subject: Re: [PSES] NFPA cybersecurity "shall be permitted"? You don't often get email from [email protected]<mailto:[email protected]>. Learn why this is important<https://aka.ms/LearnAboutSenderIdentification> External Email: Do NOT reply, click on links, or open attachments unless you recognize the sender and know the content is safe. If you believe this email may be unsafe, please click on the “Report Phishing” button on the top right of Outlook. Hi Lauren, Digging a bit, it looks like this was originally proposed as a hard requirement. See PI 22 in this doc<https://docinfofiles.nfpa.org/files/AboutTheCodes/79/79_F2023_EEI_AAA_FD_PIResponses.pdf> (you can search on "cybersecurity" to find it). This was proposed by Keith Waters from Schneider Electric, and at the time included "shall" rather than "shall be permitted".The committee statement was that "the proposed language is overly broad and restrictive." If you search on "cybersecurity" in this doc<https://docinfofiles.nfpa.org/files/AboutTheCodes/79/79_F2023_EEI_AAA_SD_PCResponses.pdf>, you can find a subsequent public comment where the same submitter revised the proposal, this time modifying the language that would have made it mandatory. The submitter's comment there states: "In reviewing the response to the original PI, I still feel that cybersecurity is essential to properly protecting industrial machinery and a consensus standard is the best way to protect these systems in lieu of 51 different requirements from the federal government and the individual states. However, I understand that we need to create a starting point to learn the best methods before setting full requirements. The change to the PI to make the requirement “shall be permitted” vs “shall” is a good first step into creating the safety and reliability protections." Even though this second comment was rejected, it references a subsequent revision with much the same language that can be found here<https://docinfofiles.nfpa.org/files/AboutTheCodes/79/79_F2023_EEI_AAA_SD_SRStatements.pdf>. On Fri, Aug 23, 2024 at 2:20 PM Ralph McDiarmid <[email protected]<mailto:[email protected]>> wrote: Sounds optional to me too. You’re allowed to do it, but you’re not required to do it. It’s Friday in Canada and Mexico too, but the way ;>) Ralph From: Lauren Crane <[email protected]<mailto:[email protected]>> Sent: Friday, August 23, 2024 1:34 PM To: [email protected]<mailto:[email protected]> Subject: [PSES] NFPA cybersecurity "shall be permitted"? Hello All, Happy Friday (US)…. There is a new section in NFPA 79 - 2024 edition – “4.10 Cybersecurity. Industrial machinery that is connected to a communication network and permitted to control any part of the machinery shall be permitted to comply with the following: (1) A cybersecurity assessment conducted on the connected system to determine vulnerabilities to cyberattacks; (2) A cybersecurity commissioning certification conducted on the connected system to ensure it is designed against cyberattacks and known vulnerabilities; (3) Documentation of the assessment and certification provided to those authorized to inspect, operate, and maintain the system” My best take at this is the whole thing is optional given the underlined “shall be permitted”. That phrase seems to mean (as it is used throughout NFPA 79) “is allowed”. But if I read it that way, it means the whole section 4.10 was added just to say one is allowed to do 3 things and it has no obligation to actually do anything, which seems off - because it is rather silly – Particularly since doing what is listed would not reasonably be questioned, so it doesn’t really need to be clarified that one is allowed to do it. Do any of you have a different take on this? Best Regards, -Lauren LAM RESEARCH CONFIDENTIALITY NOTICE: This e-mail transmission, and any documents, files, or previous e-mail messages attached to it, (collectively, "E-mail Transmission") may be subject to one or more of the following based on the associated sensitivity level: E-mail Transmission (i) contains confidential information, (ii) is prohibited from distribution outside of Lam, and/or (iii) is intended solely for and restricted to the specified recipient(s). If you are not the intended recipient, or a person responsible for delivering it to the intended recipient, you are hereby notified that any disclosure, copying, distribution or use of any of the information contained in or attached to this message is STRICTLY PROHIBITED. If you have received this transmission in error, please immediately notify the sender and destroy the original transmission and its attachments without reading them or saving them to disk. Thank you. Confidential – Limited Access and Use ________________________________ This message is from the IEEE Product Safety Engineering Society emc-pstc discussion list. To post a message to the list, send your e-mail to [email protected]<mailto:[email protected]> All emc-pstc postings are archived and searchable on the web at: https://www.mail-archive.com/[email protected]/<https://www.mail-archive.com/[email protected]/%20> Website: https://ewh.ieee.org/soc/pses/ Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to unsubscribe)<https://ewh.ieee.org/soc/pses/list.html> List rules: https://ewh.ieee.org/soc/pses/listrules.html For help, send mail to the list administrators: Mike Sherman at: [email protected]<mailto:[email protected]> Rick Linford at: [email protected]<mailto:[email protected]> For policy questions, send mail to: Jim Bacher at: [email protected]<mailto:[email protected]> ________________________________ To unsubscribe from the EMC-PSTC list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1 ________________________________ This message is from the IEEE Product Safety Engineering Society emc-pstc discussion list. To post a message to the list, send your e-mail to [email protected]<mailto:[email protected]> All emc-pstc postings are archived and searchable on the web at: https://www.mail-archive.com/[email protected]/ Website: https://ewh.ieee.org/soc/pses/ Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to unsubscribe)<https://ewh.ieee.org/soc/pses/list.html> List rules: https://ewh.ieee.org/soc/pses/listrules.html For help, send mail to the list administrators: Mike Sherman at: [email protected]<mailto:[email protected]> Rick Linford at: [email protected]<mailto:[email protected]> For policy questions, send mail to: Jim Bacher at: [email protected]<mailto:[email protected]> ________________________________ To unsubscribe from the EMC-PSTC list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1 -- Scott Aldous | Regulatory Compliance Manager | [email protected]<mailto:[email protected]> | 650-253-1994 ________________________________ This message is from the IEEE Product Safety Engineering Society emc-pstc discussion list. To post a message to the list, send your e-mail to [email protected]<mailto:[email protected]> All emc-pstc postings are archived and searchable on the web at: https://www.mail-archive.com/[email protected]/ Website: https://ewh.ieee.org/soc/pses/ Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to unsubscribe)<https://ewh.ieee.org/soc/pses/list.html> List rules: https://ewh.ieee.org/soc/pses/listrules.html For help, send mail to the list administrators: Mike Sherman at: [email protected]<mailto:[email protected]> Rick Linford at: [email protected]<mailto:[email protected]> For policy questions, send mail to: Jim Bacher at: [email protected]<mailto:[email protected]> ________________________________ To unsubscribe from the EMC-PSTC list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1 - ---------------------------------------------------------------- This message is from the IEEE Product Safety Engineering Society emc-pstc discussion list. To post a message to the list, send your e-mail to [email protected] All emc-pstc postings are archived and searchable on the web at: https://www.mail-archive.com/[email protected]/ Website: https://ewh.ieee.org/soc/pses/ Instructions: https://ewh.ieee.org/soc/pses/list.html (including how to unsubscribe) List rules: https://ewh.ieee.org/soc/pses/listrules.html For help, send mail to the list administrators: Mike Sherman at: [email protected] Rick Linford at: [email protected] For policy questions, send mail to: Jim Bacher: <[email protected]> _________________________________________________ To unsubscribe from the EMC-PSTC list, click the following link: https://listserv.ieee.org/cgi-bin/wa?SUBED1=EMC-PSTC&A=1

